2026-05
2026-05
This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar
Microsoft Security Release Radar - May 2026
π¦ Azure Container Apps
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Defender for Cloud support for Azure Container Apps (Serverless Containers Posture) | Preview | Bring Azure Container Apps environments into Defender for Cloudβs Serverless Containers Posture experience for unified posture management across the container estate. |
| π’ | Confidential Compute support on Azure Container Apps | GA | Run regulated or sensitive containerized workloads with stronger data-in-use protection via hardware-based isolation. |
| π’ | Monitor HTTP traffic in Azure Container Apps | GA | New ContainerAppHTTPLogs diagnostic setting category exposes detailed HTTP access logs for high-volume request data. |
| π’ | Additional OpenTelemetry destinations (New Relic, Dynatrace, Elastic) | GA | Enhanced OTel capabilities with expanded third-party observability platform endpoint options. |
| π’ | Override Scale Rules in Azure Functions on Azure Container Apps | GA | New allowScalingRuleOverride property lets customers override platform-managed KEDA scale rules. |
| π‘ | Azure Container Apps Sandboxes | Preview | Hyper-V isolated sandboxes for secure execution of untrusted code with pre-warmed pools and MCP integration. |
| π‘ | Azure Container Apps Express | Preview | Streamlined container runtime without environment setup, featuring sub-second startup and scale-to-zero. |
| π΅ | Running production AI agents on Azure Container Apps | New/Updated | Foundry Agent Service uses ACA as runtime for long-running, event-driven AI agents with serverless scaling and built-in security. |
| π΅ | Custom scaling control with KEDA rule overrides | New/Updated | Override platform-generated KEDA rules for full control over scaling thresholds, event sources, and multi-signal scenarios. |
| π΅ | Modernizing legacy applications to ACA | New/Updated | GitHub Copilot App Modernization reduces legacy-to-ACA migration effort from weeks to hours with managed identity and Key Vault integration. |
| π΅ | Safely executing AI-generated code with Dynamic Sessions | New/Updated | Hyper-V isolated sandboxes for AI-generated code execution with pre-warmed pools and MCP integration. |
π§± Azure Container Instances
No updates for May 2026.
β΅ AKS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΄ | AKS-2026-0004: Container Insights add-on nodes/proxy permission RCE risk | Security | Container Insights add-on uses nodes/proxy permission on AKS < v1.33, enabling potential RCE via Kubelet API. Upgrade to v1.33+ for fix. |
| π΄ | AKS-2026-0003: CVE-2026-31431 βCopy Failβ LPE advisory | Security | Local privilege escalation in Linux kernel algif_aead module (CVSS 7.8 HIGH). Requires code execution on the node. |
| π΄ | Kubernetes patch versions 1.35.4, 1.34.7, 1.33.11 with Go CVE fixes | Security | Patches address CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289. |
| π΄ | Kubernetes patch versions 1.35.5, 1.34.8, 1.33.12 | Security | Additional patch releases for Kubernetes versions. |
| π΄ | Azure Blob CSI driver security patch updates | Security | Azure Blob CSI driver updated to v1.26.12 (AKS 1.32+) and v1.27.5 (AKS 1.34+). |
| π΄ | Azure Disk CSI driver upgrade | Security | Upgraded to v1.33.10 (AKS 1.33-1.34) and v1.34.4 (AKS 1.35). |
| π΄ | Azure File CSI driver upgrade | Security | Upgraded to v1.33.10, v1.34.6, v1.35.3 across AKS versions. |
| π΄ | Cloud Provider Azure v1.36.0 update | Security | cloud-controller-manager and cloud-node-manager updated; health-probe-proxy updated to v1.36.1-1. |
| π΄ | Azure CNI Powered by Cilium update | Security | Cilium v1.19.3 (K8s 1.36+) and v1.18.9 (K8s 1.34) with security patches. |
| π΄ | ACNS DNS proxy security patch updates | Security | DNS proxy updated to v1.18.9-260520 on AKS 1.34+ addressing CVEs. |
| π΄ | Azure Policy add-on v1.15.5-1 CVE patches | Security | Patches CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2026-32280, CVE-2025-68121, CVE-2025-61726, CVE-2025-61728, CVE-2026-32281, CVE-2026-32283. |
| π΄ | Defender for Containers sensor v0.9.53 / v0.8.50 | Security | Sensor upgrades with malware scanning capability and drift detection blocking support. |
| π΄ | Defender for Containers sensor v0.10 on AKS 1.36 | Security | New sensor version available on AKS 1.36. |
| π’ | Windows Server 2025 GA on AKS | GA | Windows Server 2025 node pools now generally available on K8s 1.32+ with CLI 2.87.0+. |
| π’ | Azure Container Linux GA on AKS | GA | Azure Container Linux is now GA as an OS option on AKS starting v1.34. |
| π’ | Azure Policy add-on VAP generation | GA | Policy add-on now generates ValidatingAdmissionPolicies for CEL-based enforcement with fail-closed. |
| π’ | AKS end of support notifications | GA | Automatic notifications when cluster K8s version approaches/passes end of support, via Azure Resource Graph. |
| π‘ | Azure Linux 3.0 confidential VM preview (Fairfax) | Preview | Confidential VM support for Azure Linux 3.0 in US Gov regions. |
| π‘ | In-place node pool resize | Preview | Resize VMSS-based node pool VM size without manual migration. |
| π‘ | Automatic Pod Disruption Budget management | Preview | AKS extension auto-creates PDBs and scales up replicas to unblock node drain. |
| β« | Istio add-on asm-1-27 deprecated | Deprecation | Revision asm-1-27 of Istio service mesh add-on deprecated; upgrade to 1.28+. |
| β« | Windows Server Annual Channel for Containers retired | Deprecation | Retired May 15, 2026; migrate to LTSC by May 15, 2027. |
| β« | Windows Server 2019 retired | Deprecation | Retired March 1, 2026; no new images or security patches. Remove by April 1, 2027. |
| β« | Flatcar Container Linux for AKS retiring June 8, 2026 | Deprecation | No new images or patches after June 8, 2026; migrate to Azure Container Linux. |
| π’ | Managed system node pools GA for AKS Automatic | GA | New AKS Automatic clusters preconfigure managed system node pools with enhanced security restrictions. |
| π΅ | LocalDNS auto-enabled on K8s 1.36+ | New/Updated | LocalDNS automatically enabled on node pools running K8s 1.36+. |
| π΅ | Node Auto Provisioning LocalDNS default | New/Updated | NAP Standard SKU on K8s 1.36+ defaults to LocalDNS mode Preferred. |
| π΅ | Application routing Gateway API access logs | New/Updated | Gateways using Gateway API now write access logs to stdout by default. |
| π΅ | Application routing DNS/TLS for Gateway API | New/Updated | Supports TLS via Key Vault CSI driver and DNS A records via ExternalDNS CRDs. |
| π΅ | Migration to block/none outbound types | New/Updated | AKS now allows migration from managedNATGatewayV2 to block/none outbound types for network-isolated clusters. |
| π΅ | Pod CIDR overlap validation | New/Updated | AKS validates pod CIDR ranges against reserved IP ranges (172.30.0.0/16, 172.31.0.0/16) during create/update. |
| π΅ | Calico/Azure NPM block on K8s < 1.30 | New/Updated | Install/uninstall operations rejected on clusters running K8s earlier than 1.30. |
| π΅ | AGIC add-on subnet restriction | New/Updated | AGIC blocked from using AKS-managed aks-appgateway subnet; use dedicated subnet instead. |
| π΅ | Istio v1beta1 Gateway fix | New/Updated | Fixed βUnknown gvkβ error from admission webhook for v1beta1 Gateway resources. |
| π΅ | Multiple Standard Load Balancers orphaned nodes fix | New/Updated | Orphaned nodes now included during rebalance and distributed evenly. |
| π΅ | Karpenter/KEDA silent install failure fix | New/Updated | Cluster create/update now fails with error on Karpenter/KEDA install failure. |
| π΅ | Azure Monitor Prometheus add-on v7.0.0 | New/Updated | Updated to May 2026 release. |
| π΅ | NAP Karpenter provider v1.12.1 | New/Updated | Updated Karpenter provider for Node Auto Provisioning. |
| π΅ | AKS Windows and Linux image updates | New/Updated | Updated node images for Windows Server 2022/2025/23H2, Azure Linux v3.0, Ubuntu 22.04/24.04. |
β‘ Azure Functions
| Indicator | Feature | Type | Description |
|---|---|---|---|
| β« | TLS 1.0 and TLS 1.1 retirement in App Service, Functions, Logic Apps | Deprecation | Connections using TLS 1.0/1.1 will be rejected after May 31, 2027. Migrate to TLS 1.2+. |
| π‘ | TLS/SSL certificate support for Flex Consumption | Preview | Site-scoped certificate model with up to 3 private and 3 public certificates per function app, supporting Key Vault and managed certificates. |
| π’ | Durable Task Scheduler Consumption SKU | GA | Pay-per-use durable workflows with up to 500 actions/second, 30-day retention, and Entra ID RBAC. |
π Azure Monitor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Workspace replication private link support | New/Updated | Workspace replication now supports private links during failover, removing previous BCDR limitation for private endpoint customers. |
βοΈ Microsoft Defender Cloud Apps
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Disable informational alerts for unsanctioned app access | Preview | New toggle to suppress informational alerts for blocked unsanctioned app access while keeping blocking enforcement active. |
π§ Microsoft Copilot Studio
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Computer use for agents | GA | Agents can now automate web and desktop apps by controlling browsers and desktop applications. |
| π’ | Prompt node in agent flows | GA | Single AI call with dynamic content and model selection for translation and data extraction. |
| π’ | Microsoft 365 Copilot node | GA | Send prompts to M365 Copilot or specific agents for research and audit drafting. |
| π’ | Consent-based recording on voice agents | GA | Configurable compliance behavior and retention settings for call recording consent. |
| π’ | Agent inventory schema | GA | Discover and audit all Copilot Studio agents from admin center, API, or Azure Resource Graph. |
| π‘ | Agent readiness and issue status | Preview | Consolidated status page for publishing errors, runtime issues, and configuration blocks. |
| π’ | Asynchronous responses for agent flows | GA | Long-running processes can exceed the two-minute limit and return results asynchronously. |
| π‘ | Microsoft Entra agent identities | Preview | Auto-create Entra agent identities for scoped connector permissions, Conditional Access, and DLP. |
| π‘ | Computer use standalone tools | Preview | Modular, reusable UI automation with built-in governance and observability. |
| π‘ | Mistral Medium 3.5 as primary AI model | Preview | Experimental option alongside Anthropic, xAI, and other providers. |
π¬ Defender Container Sensor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Sensor v0.10.5 β Runtime antimalware detection and blocking GA | GA | General availability of runtime antimalware detection and blocking, Bottlerocket OS support, Nexus Baremetal compatibility, and Go dependency security upgrades. |
| π’ | Sensor v0.9.58 β Bottlerocket OS support GA | GA | Bottlerocket OS support GA, Nexus Baremetal compatibility, and Go dependency security upgrades. |
| π’ | Sensor v0.8.51 β Nexus Baremetal compatibility | GA | Improved Nexus Baremetal cluster compatibility and Go dependency security upgrades. |
π¨ Microsoft Security Exposure Management
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Senior Executive User Workstation classification | New/Updated | New predefined Device classification rule for critical assets list, identifying devices used by senior executives. |
π‘οΈ Microsoft Defender Cloud
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Private clusters protection for gated deployment, binary drift, malware detection | Preview | Defender sensor support extended to private clusters for container protection features. |
| π‘ | Malware detection for EKS and GKE nodes | Preview | Kubernetes node malware coverage expanded beyond AKS to EKS and GKE multicloud environments. |
| π’ | On-demand malware scanning of Azure Files | GA | Malware scanning for Azure Files now GA, supporting Azure portal, REST API, Logic Apps, Automation, and PowerShell. |
| π’ | Defender for Open-Source Relational Databases on AWS RDS | GA | Becomes GA June 1, 2026; billing begins for preview onboarded instances. |
| π‘ | Cloud security reporting in Microsoft Defender portal | Preview | Create, customize, and share security insights with built-in CNAPP Executive Summary and Cloud Posture reports. |
| π‘ | Scanning support for Docker Hardened container images | Preview | Preview support for scanning Docker Hardened container images. |
| π’ | Defender Experts for Servers as managed XDR | GA | Managed XDR option for on-premises and multicloud servers protected by Defender for Cloud. |
| π‘ | SQL Vulnerability Assessment Express Configuration for Azure SQL MI and Synapse | Preview | Express configuration for SQL VA on Azure SQL Managed Instance and Synapse. |
| π’ | Updated Helm installation for Defender for Containers sensor | GA | Updated Helm installation method for the Defender for Containers sensor. |
| π’ | Individual recommendations GA; legacy grouped recommendations deprecated | GA | Individual recommendations now GA; legacy grouped recommendations deprecated. |
| π’ | Daily score calculation enhancement for risk-based Cloud secure score | GA | Enhanced daily score calculation for risk-based cloud secure score. |
| π’ | Defender for Cloud integration into Defender portal | GA | Defender for Cloud now integrated into the Microsoft Defender portal. |
| π’ | Defender for Cloud and GitHub Advanced Security integration | GA | Integration between Defender for Cloud and GitHub Advanced Security now GA. |
π‘οΈ Microsoft Defender Unified SecOps
No updates for May 2026.
π― Microsoft Defender XDR
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Defender Experts for Servers as standalone offerings | GA | Managed XDR and threat hunting for on-premises and multicloud servers, now available as standalone offerings. |
| π‘ | Automatic attack disruption β device isolation | Preview | Automatic isolation of compromised devices from the network during high-confidence incidents, blocking attacker communication while keeping security services connected. |
| π΅ | Advanced hunting Take action wizard for email | New/Updated | Allow or block top-level domains and file attachment hashes in emails based on advanced hunting query results. |
| π΅ | Hunting graph identity-focused scenarios | New/Updated | New predefined scenarios for Kerberoast, AS-REP roast, domain compromise, OAuth app risks, and guest user access. |
| π‘ | Defender Chat experience | Preview | Open prompt chat assistant built into Defender for SOC analysts to investigate threats in plain language. |
π Microsoft Defender Endpoint
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Defender endpoint security for Windows 7 SP1 and Windows Server 2008 R2 SP1 | GA | [Windows] Advanced protection for legacy Windows 7 SP1 and Server 2008 R2 SP1 devices via Defender deployment tool. |
| π‘ | Enhanced exposure score in Defender Vulnerability Management | Preview | New exposure score model incorporating EPSS exploit prediction data and asset context (internet-facing status, criticality). |
| π‘ | Schedule antivirus scans on Linux | Preview | [Linux] Configure scheduled quick and full scans via managed JSON, Defender portal, or mdatp CLI. |
| π‘ | Automatic device isolation (automatic attack disruption) | Preview | Automatic isolation of compromised devices blocking most network traffic while keeping security services connected. |
| π’ | Custom data collection | GA | Rule-based telemetry collection expansion beyond defaults; max event limit increased from 25,000 to 75,000 events per device per 24 hours. |
| π’ | Configure offline security intelligence update settings for Linux from portals | GA | [Linux] Configure offline security intelligence update settings from Defender and Intune portals. |
| π‘ | Selective Response Actions | Preview | Tailor high-impact security operations on Tier-0 systems and high-value assets during onboarding. |
| π’ | Windows Defender Antivirus Platform 4.18.26040.7 / Engine 1.1.26040.8 | GA | [Windows] See enhancements and features for this release. |
πΏ MDE Detailed Releases
Windows
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Fixed remote-share file scans missing detections via symlink | New/Updated | [Windows] Fixed remote-share file scans missing detections when files were accessed through a symlink. |
| π΅ | Fixed mpcmdrun -scan non-ASCII character display | New/Updated | [Windows] Fixed mpcmdrun -scan output incorrectly displaying non-ASCII characters in localized paths and threat names. |
| π΅ | Fixed network protection watchdog timers | New/Updated | [Windows] Fixed network protection watchdog timers silently not firing. |
macOS
No updates for May 2026.
Linux
No updates for May 2026.
π’ Microsoft Entra ID
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Soft-delete for Microsoft Entra Device objects | Preview | Recoverable device deletion with defined retention period, preserving device identity and security artifacts for Entra joined, registered, and hybrid joined devices. |
| π΅ | NetBiosName resolution test reclassified to informational | New/Updated | NetBIOS Name Sysvol Connectivity test in AD DS health monitoring agent changed from alerting to informational-only to reduce alert noise. |
| π΅ | Enhanced admin authorization for Entra Connect Sync changes | New/Updated | Interactive admin sign-in required for sync configuration changes via wizard or PowerShell, strengthening authorization model. |
| π΅ | Workload identity-based authentication for SAP SuccessFactors | New/Updated | Transition from basic auth to Entra workload identity with short-lived tokens for SAP SuccessFactors provisioning, ahead of SAPβs November 2026 basic auth deprecation. |
| π‘ | Sensitivity labels for Microsoft Entra security groups | Preview | Apply Purview sensitivity labels to Entra cloud security groups to govern guest access settings. |
| π’ | Account Discovery for connected applications | GA | Visibility into all accounts (including orphan accounts) within connected applications via provisioning discovery reports. |
| π’ | Cross tenant group synchronization | GA | Synchronize security groups across Entra tenants for centralized group management and cross-tenant collaboration. |
| π΅ | Modernized My Account pages | New/Updated | Redesigned Devices, Personal Info, and Organizations pages with improved BitLocker key visibility and organization leave functionality. |
| π΅ | Passkeys (FIDO2) support in registration campaign | GA | Registration campaigns now support passkeys as an authentication method, driving passkey adoption at scale. |
| π΅ | Automate user attribute updates in Lifecycle Workflows | New/Updated | New User Attribute Updates task for automated attribute value setting/clearing within lifecycle workflows. |
| π΅ | System-preferred authentication expanded to first-factor | GA | System-preferred authentication now covers first-factor sign-in, enabling passwordless sign-in for users with phishing-resistant credentials. |
| π΅ | High Scale Compatibility mode for External ID | GA | Enables migration from Azure AD B2C to Entra External ID while preserving existing user directory for large-scale customer identity platforms. |
| π΅ | Expanded policy storage for passkeys (FIDO2) | New/Updated | Dedicated 20-KB policy allocation for passkeys; max passkey profiles increased from 3 to 10. |
| π΅ | Azure Role assignments governed via Entitlement Management | New/Updated | Govern Azure role assignments at MG/Sub/RG level through access packages with request, approval, and lifecycle governance. |
| π΅ | Manage Agent ID sponsorship lifecycle with Lifecycle Workflows | GA | Automatic sponsorship transfer to manager when sponsor leaves; lifecycle workflows for agent identity sponsor notifications. |
π Microsoft Fabric
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Eventstream Business Events publisher | Preview | Publish governed, discoverable business signals from Eventstream canvas with filtering, aggregation, and thresholding. |
| π‘ | Service principal support for Fabric data agents | Preview | SPN authentication for Fabric data agents enabling application identity API calls instead of delegated user tokens. |
ποΈ Microsoft Foundry
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Trace-based evaluation for external and hosted agents | New/Updated | Grade real production traces from Foundry, GCP, AWS, or any framework without hand-curated datasets. |
| π΅ | Grok 4.3 model availability | New/Updated | xAIβs latest model available in Foundry for advanced agentic and domain-specific workloads. |
| π΅ | DeepSeek V4 model family | New/Updated | DeepSeekβs newest model family expands open-model choice in the catalog. |
| π΅ | GPT-5 Reinforcement Fine-Tuning (Gated GA) | GA | RFT graduates to gated GA with enterprise-ready compliance and SLA coverage. |
| π’ | Managed VNET GA | GA | Microsoft-managed network isolation reaches general availability. |
| π΅ | Project-level cost attribution | New/Updated | See LLM costs by project for budget tracking and governance. |
| π΅ | Content Understanding improvements GA | GA | Read and layout analyzers reach GA alongside Logic App connector and Foundry NextGen integration. |
| π΅ | Foundry Agent Service SDK 2.2.0 | New/Updated | Preview skills and toolboxes; external agent definitions across Python, JS/TS, and .NET. |
π Microsoft Defender Identity
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Sensor v3.x supports all identity roles on domain controllers | New/Updated | Sensor v3.x now supports DCs running Entra Connect, AD FS, and AD CS identity roles. |
| π΅ | Increased sensor capacity (1,000 per workspace) | New/Updated | Sensor limit increased from 350 to 1,000 per workspace. |
| π΅ | New security alerts for Entra ID | New/Updated | Eight new alerts: guest user promoted to member, user created as Global Admin, failed credential abuse, randomized user agent sign-in, stolen session cookie (detect + replay), Conditional Access bypass via non-compliant device, suspicious third-party MFA method addition. |
| π΅ | Known limitation: Windows Server 2025 sensor v2βv3 migration unsupported | New/Updated | Migration of DCs running Windows Server 2025 from sensor v2.x to v3.x not supported; continue using v2.x. |
π± Microsoft Intune
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Multi Admin Approval enforces on API calls by automation | New/Updated | MAA now applies to Microsoft Graph API calls from service principals and automation; missing approval headers return HTTP 403. |
| π΅ | Intune RBAC roles inherit Copilot access | New/Updated | Intune Administrator role gets Security Copilot owner access; all other Intune RBAC roles get contributor access automatically. |
| π΅ | Guidance for device-reported values in compliance reports | New/Updated | Updated documentation clarifying device-reported values as informational with security considerations. |
| π΅ | Complete Platform SSO registration during macOS ADE | New/Updated | [macOS] Platform SSO during Automated Device Enrollment for immediate Entra ID resource access at desktop. |
| π΅ | Enhanced app inventory with faster data updates | New/Updated | [Windows] Faster, more detailed app inventory with richer metadata and device inclusion controls. |
π Azure Logic Apps
| Indicator | Feature | Type | Description |
|---|---|---|---|
| β« | TLS 1.0 and TLS 1.1 retirement | Deprecation | Connections using TLS 1.0/1.1 will be rejected after May 31, 2027. Migrate to TLS 1.2+. |
π§ Microsoft Defender Office 365
No updates for May 2026.
π Microsoft Purview
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Data security and compliance protections for Microsoft Agent 365 | GA | GA of data security and compliance protections for Microsoft Agent 365. |
| π’ | Standalone data asset data quality scan | GA | GA of standalone data quality scanning for data assets. |
| π’ | Incremental data quality scan | GA | GA of incremental data quality scanning. |
| π’ | Configurable data quality thresholds | GA | GA of configurable thresholds for data quality rules and assets. |
| π΅ | DLP admin permissions for unmanaged cloud apps in Edge | New/Updated | Added Directory Reader, Edge, and Intune admin permissions required for DLP activation in Edge for Business. |
| π΅ | Edge browser profile scope clarification for cloud DLP | New/Updated | Policies for unmanaged apps apply across all Edge profiles; managed apps apply only in work profile. |
| π΅ | DeepL and Zapier removed from unmanaged AI apps list | New/Updated | Removed DeepL and Zapier from supported unmanaged AI apps for Edge browser DLP. |
| π‘ | Block access for specific external domains/users in DLP | Preview | New sub-option for SharePoint/OneDrive DLP to block sensitive file access for specific external domains or user SMTPs. |
| π΅ | OCR support in Data Security Investigations | New/Updated | Image files automatically processed with OCR; extracted text merged and vectorized for AI analysis. |
| π΅ | Custom examinations in Data Security Investigations | New/Updated | Define custom examination focus with prompts beyond built-in examination areas. |
| π΅ | Large audit search result guidance | New/Updated | Guidance for working with audit searches exceeding ~3,000-item limit using Audit solution and time-based slices. |
| π’ | Data Security Posture Management new version GA | GA | New DSPM version GA with guided workflows for proactive risk management; partner solutions and DSPM Agent remain in preview. |
| π΅ | Administrative unit support in DSPM | New/Updated | Support for administrative units in DSPM, bringing parity with classic versions. |
| π΅ | Inactive tenant data processing pause | New/Updated | Processing paused for M365 data after 60 days of tenant inactivity; auto-resumes on return. |
| π΅ | Anthropic Claude (Enterprise) data connector | New/Updated | Support for Anthropic Claude as AI application in activity explorer alongside Copilot, ChatGPT Enterprise, and others. |
| π‘ | Scanner cluster-level feature control via PowerShell | Preview | Enable, disable, and configure cluster-level scanner features from PowerShell. |
| π‘ | Custom Reporting for scanner | Preview | Additional columns and tables in scanner database for custom Power BI or SQL-based reports. |
| π‘ | Custom posture reports | Preview | Build tailored views of information protection and DLP activity with metric and chart cards. |
| π‘ | Manual labeling for MP4 files | Preview | Rolling out manual sensitivity labeling support for MP4 files in SharePoint and OneDrive. |
| π‘ | Meeting label policy for artifacts | Preview | Auto-apply meeting sensitivity label to recordings, transcripts, and notes. |
| π‘ | Label policy sync status visibility | Preview | See sync status of sensitivity label publishing policies on Label policies page. |
| π΅ | Sensitivity label disable documentation update | New/Updated | Updated documentation for disabling sensitivity labels for SharePoint and OneDrive after enablement. |
| π΅ | Auto-labeling policy-level activity monitoring | New/Updated | Per-policy review pages for daily labeling activity, spot-checking, and failure investigation. |
π€ Microsoft Security Copilot
No updates for May 2026.
π Microsoft Sentinel
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Generate playbooks using AI | GA | SOAR playbook generator creates Python-based automation workflows through conversational AI with Cline coding agent. |
| π΅ | UEBA enhancements: new settings, Okta V2, GCP anomalies | New/Updated | New consolidated UEBA settings view; Okta V2 table support for anomaly detections; five new GCP Audit Logs anomaly detections for unusual login, privileged actions, resource deployments, secret/KMS access, and infrastructure patterns. |
Top 5 Action Items
| Priority | Action | Due | Affected Product(s) |
|---|---|---|---|
| π΄ | Upgrade AKS clusters to v1.33+ if Container Insights is enabled to eliminate nodes/proxy RCE risk | Immediate | AKS |
| π΄ | Apply AKS patch versions 1.35.5/1.34.8/1.33.12 to address Go CVEs (CVE-2026-27140 et al.) | Immediate | AKS |
| π΄ | Migrate Windows Server Annual Channel node pools to LTSC before support removal | May 15, 2027 | AKS |
| π΄ | Migrate Flatcar Container Linux node pools to Azure Container Linux | June 8, 2026 | AKS |
| π΄ | Plan TLS 1.0/1.1 migration to TLS 1.2+ for App Service, Functions, and Logic Apps | May 31, 2027 | Azure Functions, Logic Apps |
Security Architect Observations
- AKS nodes/proxy RCE (AKS-2026-0004) is the highest-severity item this month. The Container Insights add-onβs use of
nodes/proxyon clusters < v1.33 creates a genuine RCE path via the Kubelet API. The fix requires a cluster upgrade to v1.33+ where fine-grainednodes/podssubresource authorization (KEP-2862) is available. For clusters that cannot upgrade immediately, restrict pod network access to port 10250 as defense-in-depth. - CVE-2026-31431 βCopy Failβ (CVSS 7.8) is a local privilege escalation in the Linux kernelβs
algif_aeadmodule affecting AKS nodes. While the attack vector requires local code execution, container breakout scenarios make this relevant. Ensure node images are patched via the May AKS release cycle. - Entra Connect Sync interactive admin authorization represents a meaningful security hardening for hybrid identity. Requiring interactive authentication for sync configuration changes closes a gap where stale or compromised credentials could modify sync settings. Plan for the operational impact on automation scripts and scheduled sync tasks.
- TLS 1.0/1.1 deprecation across App Service, Functions, and Logic Apps (effective May 31, 2027) requires a systematic inventory of all clients and services connecting to these services. Use the Azure Retirement Workbook to identify affected resources and plan client-side TLS stack upgrades.
- Defender for Containers sensor v0.10 on AKS 1.36 introduces GA runtime antimalware detection and blocking. This is a significant defense-in-depth addition for container workloads. Evaluate enabling malware scanning on production clusters, considering the performance and cost implications.
Security Operations Observations
- Eight new Defender for Identity alerts focused on Entra ID provide critical coverage for identity-based attacks: session cookie theft/replay, Conditional Access bypass, guest account elevation, and suspicious MFA method additions. Review these alert rules and tune severity levels; consider creating automated response playbooks for the session cookie and Global Admin creation alerts.
- Automatic attack disruption with device isolation (Defender XDR preview) changes the SOC workflow for high-confidence incidents. Devices will be automatically network-isolated while retaining connectivity to security services. Ensure your SOC has runbooks for reviewing and releasing automatic isolations, and test the feature in a controlled environment before broad enablement.
- Sentinel UEBA GCP anomaly detections add five new detection types for GCP Audit Logs. If you monitor GCP environments, enable these detections and establish baselines for unusual login behavior, privileged actions, and resource deployment patterns to avoid false positive floods.
- Defender for Cloud malware detection for EKS and GKE nodes (preview) extends container node malware coverage beyond AKS. Multi-cloud SOC teams should enable this preview and integrate alerts into their existing Kubernetes incident response workflows.
- Purview DLP block for specific external domains/users (preview) on SharePoint and OneDrive gives SOC teams granular control over external data sharing. Review current external sharing policies and consider enabling this for high-risk domains or known bad actors.
- Intune Multi Admin Approval enforcement on API calls will break automation scripts that modify protected Intune resources without the MAA approval workflow. Identify all service principals and automation using Graph API for Intune and update them to include approval headers or exclude them via the Exclusions tab.
References
This post is licensed under CC BY 4.0 by the author.